Skip to content

Campaign record

MintsLoader from Storm-0426

MintsLoader pushed at German recipients by Storm-0426 through a Prometheus TDS

Status as last assessed
Active
First seen
2025-03-26
Last seen
2025-03-26
Indicators
2
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Invoice or payment pretext
  • MintsLoader
  • Phishing email
  • Traffic distribution system (TDS)

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

In March 2025 Microsoft watched the group it tracks as Storm-0426 send thousands of messages to recipients in Germany. The pretext was a bill from a web hosting company, and the link went not to the lure but to a Prometheus traffic direction system standing on a spread of broken-into sites. Visitors who passed through it landed on mein-lonos-cloude[.]de, a name that plays on a German hosting brand and which Microsoft states the attacker controlled. There the ClickFix routine asked for a human verification step; carrying out the displayed steps ran the operator's code. The goal was MintsLoader, a loader whose purpose is to bring down further malware once it has a foothold. Microsoft records derko-meru[.]online as the loader's controller. Both names were observed on 26 March 2025.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
1 of 2
Checks recorded
2
Checks since publication
2
Never checked
1

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 1 indicator has never been checked by us at all.

Current recorded state

  • 1 Unregistered
  • 1 Not checked by us

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Indicators

2 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenStateReport an error
domain, shown defanged for safety: mein-lonos-cloude dot dedomainLure pageAttacker-controlled2025-03-262025-03-26Unregistered2026-08-22Report an error in domain record 5a40b77e-4947-4ff3-9333-a6e2e7e370fd
domain, shown defanged for safety: derko-meru dot onlinedomainCommand and controlNot yet assessed2025-03-262025-03-26Not checked by usReport an error in domain record 5c69886f-6724-42e5-8712-13066eacb6ca

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or a recorded execution mechanism. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “MintsLoader from Storm-0426”, campaign ID daec320f, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/daec320f/mintsloader-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.